Show filters
557 Total Results
Displaying 161-170 of 557
Sort by:
Attacker Value
Unknown

CVE-2022-2221

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
Information Exposure vulnerability in My Account Settings of Devolutions Remote Desktop Manager before 2022.1.8 allows authenticated users to access credentials of other users. This issue affects: Devolutions Remote Desktop Manager versions prior to 2022.1.8.
Attacker Value
Unknown

CVE-2022-28167

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
Brocade SANnav before Brocade SANvav v. 2.2.0.2 and Brocade SANanv v.2.1.1.8 logs the Brocade Fabric OS switch password in plain text in asyncjobscheduler-manager.log
Attacker Value
Unknown

CVE-2022-34213

Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2022-34202

Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Jenkins EasyQA Plugin 1.0 and earlier stores user passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2022-34199

Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2022-1666

Disclosure Date: June 23, 2022 (last updated February 24, 2025)
The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was used to crack the password using a widely available open-source tool.
Attacker Value
Unknown

CVE-2022-2103

Disclosure Date: June 23, 2022 (last updated February 24, 2025)
An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive files and write to remotely executable directories.
Attacker Value
Unknown

CVE-2022-33953

Disclosure Date: June 22, 2022 (last updated February 24, 2025)
IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected access tokens. IBM X-Force ID: 229198.
Attacker Value
Unknown

CVE-2020-28865

Disclosure Date: June 16, 2022 (last updated February 23, 2025)
An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parameter to /appinfo/save.
Attacker Value
Unknown

CVE-2022-31044

Disclosure Date: June 15, 2022 (last updated February 23, 2025)
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. The Key Storage converter plugin mechanism was not enabled correctly in Rundeck 4.2.0 and 4.2.1, resulting in use of the encryption layer for Key Storage possibly not working. Any credentials created or overwritten using Rundeck 4.2.0 or 4.2.1 might result in them being written in plaintext to the backend storage. This affects those using any `Storage Converter` plugin. Rundeck 4.3.1 and 4.2.2 have fixed the code and upon upgrade will re-encrypt any plain text values. Version 4.3.0 does not have the vulnerability, but does not include the patch to re-encrypt plain text values if 4.2.0 or 4.2.1 were used. To prevent plaintext credentials from being stored in Rundeck 4.2.0/4.2.1, write access to key storage can be disabled via ACLs. After upgrading to 4.3.1 or later, write access can be restored.